ftrace: Fix null pointer dereference in ftrace_add_mod()
Published May 1, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
The @ftrace_mod is allocated by kzalloc(), so both the members {prev,next} of @ftrace_mode->list are NULL, it's not a valid state to call list_del(). If kstrdup() for @ftrace_mod->{func|module} fails, it goes to @out_free tag and calls free_ftrace_mod() to destroy @ftrace_mod, then list_del() will write prev->next and next->prev, where null pointer dereference happens.
BUG: kernel NULL pointer dereference, address: 0000000000000008 Oops: 0002 [#1] PREEMPT SMP NOPTI Call Trace: <TASK> ftrace_mod_callback+0x20d/0x220 ? do_filp_open+0xd9/0x140 ftrace_process_regex.isra.51+0xbf/0x130 ftrace_regex_write.isra.52.part.53+0x6e/0x90 vfs_write+0xee/0x3a0 ? __audit_filter_op+0xb1/0x100 ? auditd_test_task+0x38/0x50 ksys_write+0xa5/0xe0 do_syscall_64+0x3a/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd Kernel panic - not syncing: Fatal exception
So call INIT_LIST_HEAD() to initialize the list member to fix this issue.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.13
- Version 4.14.300StatusunaffectedConstraints<=4.14.*
- Version 4.19.267StatusunaffectedConstraints<=4.19.*
- Version 5.10.156StatusunaffectedConstraints<=5.10.*
- Version 5.15.80StatusunaffectedConstraints<=5.15.*
- Version 5.4.225StatusunaffectedConstraints<=5.4.*
- Version 6.0.10StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.13 · < 4.14.300
- ≥ 4.15 · < 4.19.267
- ≥ 4.20 · < 5.4.225
- ≥ 5.5 · < 5.10.156
- ≥ 5.11 · < 5.15.80
- ≥ 5.16 · < 6.0.10
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The patch fixes a kernel NULL pointer dereference in the ftrace_add_mod() function. When memory allocation (kzalloc()) succeeds but subsequent kstrdup() fails, the error path calls list_del() on an uninitialized list head (ftrace_mod->list). This leads to a kernel panic due to prev->next or next->prev being NULL. This bug can be triggered by local privileged users (typically those interacting with Ftrace via debugfs or similar kernel tracing interfaces).
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.22% (0.00222) | 11.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.18% (0.00182) | 7.94th | v5 (v2026.06.15) |
| May 2, 2025 | 0.02% (0.00024) | 5.15th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2022-49802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363471 Issue Tracking
- https://git.kernel.org/stable/c/19ba6c8af9382c4c05dc6a0a79af3013b9a35cd0 Patch
- https://git.kernel.org/stable/c/1bea037a1abb23a6729bef36a2265a4565f5ea77 Patch
- https://git.kernel.org/stable/c/665b4c6648bf2b91f69b33817f4321cf4c3cafe9 Patch
- https://git.kernel.org/stable/c/6a14828caddad0d989495a72af678adf60992704 Patch
- https://git.kernel.org/stable/c/6e50eb4b1807017f6c2d5089064256ce2de8aef1 Patch
- https://git.kernel.org/stable/c/b5bfc61f541d3f092b13dedcfe000d86eb8e133c Patch
- https://git.kernel.org/stable/c/f715f31559b82e3f75ce047fa476de63d8107584 Patch
- https://lore.kernel.org/linux-cve-announce/2025050126-CVE-2022-49802-ee41@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49802
- https://www.cve.org/CVERecord?id=CVE-2022-49802
Change history (0)
No recorded changes yet.